You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何启动OpenSSL CMP模拟服务器?启动命令报错求助

启动OpenSSL CMP模拟服务器报错排查与解决

问题场景

尝试执行以下命令启动OpenSSL CMP模拟服务器:

openssl cmp -port 8080 -srv_trusted test-ca-cert.pem 
            -srv_key test-server-key.pem -srv_cert test-server-cert.pem 
            -rsp_cert test-client-cert2.pem -rsp_capubs test-ca-cert.pem &

执行后出现错误:

Error:-
cmp_main:apps\cmp.c:2751:CMP info: using section(s) 'cmp' of OpenSSL configuration file 'C:\Program Files\Common Files\SSL/openssl.cnf'
cmp_main:apps\cmp.c:2760:CMP info: no [cmp] section found in config file 'C:\Program Files\Common Files\SSL/openssl.cnf'; will thus use just [default] and unnamed section if present
setup_srv_ctx:apps\cmp.c:1030:CMP warning: mock server will not be able to handle PBM-protected requests since -srv_secret is not given
Could not open file or uri for loading certificate of the mock server from test-server-cert.pem
60410000:error:16000069:STORE routines:ossl_store_get0_loader_int:unregistered scheme:crypto\store\store_register.c:237:scheme=file
60410000:error:80000002:system library:file_open:No such file or directory:providers\implementations\storemgmt\file_store.c:267:calling stat(test-server-cert.pem)
Unable to load certificate of the mock server

核心问题定位

错误日志中No such file or directory: calling stat(test-server-cert.pem)是启动失败的直接原因,说明OpenSSL无法找到指定的证书文件。其余提示为非致命性警告,不影响服务器启动,可后续按需处理。

解决步骤

  • 确认文件存在与路径正确性

    1. 执行命令前,先检查当前工作目录下是否存在test-server-cert.pem、test-server-key.pem等所有指定文件。Windows用dir命令,Linux/macOS用ls命令查看。
    2. 如果文件不在当前目录,使用绝对路径指定文件位置。例如Windows环境下:
      openssl cmp -port 8080 -srv_trusted "C:\certificates\test-ca-cert.pem" 
                  -srv_key "C:\certificates\test-server-key.pem" -srv_cert "C:\certificates\test-server-cert.pem" 
                  -rsp_cert "C:\certificates\test-client-cert2.pem" -rsp_capubs "C:\certificates\test-ca-cert.pem" &
      
      注意路径包含空格时,需用双引号包裹避免参数解析错误。
  • 检查文件读取权限

    1. Windows系统:右键目标证书文件→属性→安全标签,确认当前执行命令的用户拥有读取权限。
    2. Linux/macOS系统:执行chmod +r test-server-cert.pem(对应其他文件同理),赋予文件读取权限。
  • 次要警告处理(可选)

    • 针对no [cmp] section found in config file:若无需自定义CMP规则,可直接忽略;若需要,在openssl.cnf中添加[cmp] section并配置相关参数。
    • 针对mock server will not be able to handle PBM-protected requests:若需支持PBM保护请求,在命令中添加-srv_secret <你的PBM密钥>参数即可。

内容的提问来源于stack exchange,提问作者Neeraj Gahlawat

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 17:40:36